Tenable.ot Family for Tenable OT Security

IDNameSeverity
502412Synology DiskStation Manager Sudo Off-by-one Error (CVE-2021-3156)
high
502411Synology DSM HTTP/2 Implementations Allocation of Resources Without Limits or Throttling (CVE-2019-9516)
medium
502410Synology DiskStation Manager SQL Injection (CVE-2021-43925)
critical
502409Synology DiskStation Manager Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2022-27624)
critical
502408Synology DiskStation Manager Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2022-27625)
critical
502407Synology DiskStation Manager Weak Password Recovery Mechanism for Forgotten Password (CVE-2018-8916)
high
502406Synology DiskStation Manager SQL Injection (CVE-2021-43926)
critical
502405Synology DiskStation Manager Improper Limitation of a Pathname to a Restricted Directory (CVE-2017-15894)
medium
502404Synology DiskStation Manager Classic Buffer Overflow (CVE-2022-22687)
critical
502403Synology DiskStation Manager Missing Authentication for Critical Function (CVE-2022-27623)
critical
502402Synology DiskStation Manager Improper Neutralization of Special Elements used in a Command (CVE-2017-12075)
high
502401Synology DiskStation Manager Injection (CVE-2021-29084)
high
502400Synology DiskStation Manager Cross-site Scripting (CVE-2015-4655)
medium
502399Synology DiskStation Manager Sensitive Cookie in HTTPS Session Without 'Secure' Attribute (CVE-2020-27650)
low
502398Synology DiskStation Manager Use of Insufficiently Random Values (CVE-2023-2729)
high
502397Synology DiskStation Manager Debian Linux Race Condition (CVE-2018-8897)
high
502396Synology DiskStation Manager Improper Neutralization of Input During Web Page Generation (CVE-2021-43929)
medium
502395Synology DiskStation Manager Credentials Management Errors (CVE-2010-3684)
low
502394Synology DiskStation Manager NTPD Denial of Service (CVE-2018-7185)
high
502393Synology DiskStation Manager Out-of-bounds Read (CVE-2022-3576)
high
502392Synology DSM HTTP/2 Implementations Allocation of Resources Without Limits or Throttling (CVE-2019-9515)
high
502391Siemens Third Party Component in SICAM products Copy without Checking Size of Input (CVE-2024-34057)
high
502390Cognex In-Sight OPC Server Deserialization of Untrusted Data (CVE-2021-32935)
critical
502389Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380 Improper Input Validation (CVE-2024-6077)
high
502388Sony Network Cameras OS Command Injection (CVE-2018-3937)
high
502387Sony Network Cameras Stack-based Buffer Overflow (CVE-2018-3938)
critical
502386Dell 2335dn printer Weak Password Requirements (CVE-2018-15748)
high
502385Dell Laser Printer 2335dn and 2355dn Improper Neutralization of Input During Web Page Generation (CVE-2017-14386)
medium
502384Beckhoff TwinCAT/BSD Authentication Bypass Using an Alternate Path or Channel (CVE-2024-41173)
high
502383Beckhoff TwinCAT/BSD Buffer Copy without Checking Size of Input (CVE-2024-41176)
high
502382Beckhoff TwinCAT/BSD Improper Neutralization of Input During Web Page Generation (CVE-2024-41174)
high
502381Beckhoff TwinCAT/BSD Allocation of Resources Without Limits or Throttling (CVE-2024-41175)
medium
502380Nexans FTTO GigaSwitch Backdoor Account (CVE-2022-32985)
critical
502379ABB Freelance AC 900F and AC 700F Numeric Range Comparison Without Minimum Check (CVE-2023-0425)
high
502378ABB Freelance AC 900F and AC 700F Stack-based Buffer Overflow (CVE-2023-0426)
high
502377SEH Computertechnik UTN Server PRO and INU-100 Denial of Service (CVE-2024-5422)
high
502376SEH Computertechnik UTN Server PRO and INU-100 OS Command Injection (CVE-2024-5421)
high
502375SEH Computertechnik UTN Server PRO and INU-100 Stored Cross-Site Scripting (CVE-2024-5420)
high
502374Emerson Ovation Insufficient Verification of Data Authenticity (CVE-2022-30267)
critical
502373Emerson Ovation Missing Authentication for Critical Function (CVE-2022-29966)
critical
502372Rockwell Automation ControlLogix, GuardLogix 5580, CompactLogix, and Compact GuardLogix 5380 Improper Input Validation (CVE-2024-7515)
high
502371Rockwell Automation ControlLogix, GuardLogix 5580, CompactLogix, Compact GuardLogix 5380 Improper Input Validation (CVE-2024-7507)
medium
502370Siemens LOGO! V8.3 BM Devices Plaintext Storage of a Password (CVE-2024-39922)
medium
502369Rockwell Automation GuardLogix/ControlLogix 5580 Controller Improper Check For Unusual or Exceptional Conditions (CVE-2024-40619)
high
502368Schneider Electric Modicon M340, BMXNOE0100 and BMXNOE0110 Files or Directories Accessible to External Parties (CVE-2024-5056)
medium
502367Siemens SCALANCE M-800, RUGGEDCOM RM1224 Improper Input Validation (CVE-2024-41976)
high
502366Siemens SCALANCE M-800, RUGGEDCOM RM1224 Exposure of Data Element to Wrong Session (CVE-2024-41977)
high
502365Siemens SCALANCE M-800, RUGGEDCOM RM1224 Insertion of Sensitive Information Into Log File (CVE-2024-41978)
medium
502364Dahua Security Multiple Products Improper Input Validation (CVE-2024-39944)
high
502363Dahua Security Multiple Products Improper Input Validation (CVE-2024-39950)
critical